{"id":13389,"date":"2026-06-05T05:03:33","date_gmt":"2026-06-05T05:03:33","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/05\/hacking-metas-ai-chatbot-html\/"},"modified":"2026-06-05T05:03:33","modified_gmt":"2026-06-05T05:03:33","slug":"hacking-metas-ai-chatbot-html","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/05\/hacking-metas-ai-chatbot-html\/","title":{"rendered":"Hacking Meta\u2019s AI Chatbot"},"content":{"rendered":"\n<div>Hacking Meta\u2019s AI Chatbot<\/div>\n<p> \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Hackers are <a href=\"https:\/\/techcrunch.com\/2026\/06\/01\/hackers-hijacked-instagram-accounts-by-tricking-meta-ai-support-chatbot-into-granting-access\/\">convincing<\/a> Meta\u2019s AI support chatbot to let them take over other peoples\u2019 accounts:<\/p>\n<blockquote>\n<p>A <a href=\"https:\/\/x.com\/DarkWebInformer\/status\/2061253599758315527\">video<\/a> posted on X showed the step-by-step process to hack someone\u2019s Instagram account. The hacker allegedly used a VPN to spoof the targets\u2019 presumed location to avoid triggering Instagram\u2019s automated account protections. Then, the hacker opened a chat with Meta AI Support Assistant and asked the bot to add a new email address to the target\u2019s account. The chatbot can be seen sending a verification code to the email address provided by the hacker; the hacker then shares the verification code with the chatbot, which prompts the chatbot to show a button to \u201cReset Password.\u201d The hacker enters a new password and takes over the victim\u2019s account.<\/p>\n<p>[\u2026]<\/p>\n<p>On Monday, Instagram spokesperson Andy Stone said in <a href=\"https:\/\/x.com\/andymstone\/status\/2061489833441145103\">a reply<\/a> to Wong\u2019s post and others that the issue was now fixed. It\u2019s unclear how many Instagram users had their accounts improperly accessed. <\/p>\n<\/blockquote>\n<p>It\u2019s not that easy. Probably this particular tactic is now blocked. But there are others, many others, and they cannot be blocked as a class. The real problem is that LLM chatbots are not trustworthy enough for this application.<\/p>\n<p>Another news <a href=\"https:\/\/www.404media.co\/hackers-simply-asked-meta-ai-to-give-them-access-to-high-profile-instagram-accounts-it-worked\/\">article<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Bruce Schneier<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/www.schneier.com\/blog\/archives\/2026\/06\/hacking-metas-ai-chatbot.html\">Go to bruce schneier<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hacking Meta\u2019s AI Chatbot Hackers are convincing Meta\u2019s AI support chatbot to let them take over other peoples\u2019 accounts: A video posted on X showed the step-by-step process to hack someone\u2019s Instagram account. The hacker allegedly used a VPN to spoof the targets\u2019 presumed location to avoid triggering Instagram\u2019s automated account protections. Then, the hacker [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[167,57,2250,464,97,268,1210,1],"tags":[87],"class_list":["post-13389","post","type-post","status-publish","format-standard","hentry","category-ai","category-bruce-schneier","category-chatbots","category-cybersecurity","category-hacking","category-llm","category-meta","category-uncategorized","tag-bruce-schneier"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13389"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13389"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13389\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13389"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13389"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13389"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}